<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network Feeds and VSX in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247400#M41347</link>
    <description>&lt;P&gt;Im pretty sure its fine, did not see any limitations about it in below link.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 26 Apr 2025 03:37:23 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-26T03:37:23Z</dc:date>
    <item>
      <title>Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/212877#M35214</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have just created a network feed object and went to test that I had defined it correctly. When I tested it, I was shown only the non VSX gateways. this matches up with what is said in here...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm&amp;nbsp;&lt;/A&gt;being&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;Note - The "Select gateway" menu does not show these VSX&amp;nbsp; Virtual Devices: Virtual Systems, Virtual Routers, Virtual Switches.&lt;/EM&gt;"&lt;BR /&gt;&lt;BR /&gt;My question, are network feeds supported on VSX?, ie while we cannot select a VSX gatey to test the feed, if we install the policy it will work?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 02:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/212877#M35214</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2024-05-02T02:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/212880#M35215</link>
      <description>&lt;P&gt;External Network Feeds is listed as "NO" in&amp;nbsp;sk79700 but would recommend validating with your SE / TAC as appropriate.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 03:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/212880#M35215</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-05-02T03:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213040#M35239</link>
      <description>&lt;P&gt;I had not noticed sk79700 mentioned by Chris and I pushed the policy without using the test feed and it worked, it downloaded the file and started blocking traffic as expected.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Now the question is if we are supported by TAC when we use this feature, if it breaks anything etc. for me is one of the most important features in r81.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 04:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213040#M35239</guid>
      <dc:creator>jkougoulos</dc:creator>
      <dc:date>2024-05-03T04:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213041#M35240</link>
      <description>&lt;P&gt;How long have&amp;nbsp; you had it running in this way? days/weeks/months?&lt;BR /&gt;&lt;BR /&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 04:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213041#M35240</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2024-05-03T04:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213042#M35241</link>
      <description>&lt;P&gt;Official VSX support for Network Feeds can best be described as "complicated."&lt;/P&gt;
&lt;P&gt;If you have a regular (non-VSX) gateway to test the Network Feed, you can install it to a VSX gateway.&lt;BR /&gt;VSX gateways cannot validate Network Feeds at this time.&lt;BR /&gt;If you only have VSX gateways, you basically can't use Network Feeds.&lt;BR /&gt;This is why the documentation currently says it is unsupported on VSX.&lt;/P&gt;
&lt;P&gt;The above was confirmed with R&amp;amp;D.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 05:29:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213042#M35241</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-03T05:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213048#M35243</link>
      <description>&lt;P&gt;Just days. But based on the answer from&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, probably I will have to remove it as we only have VSX&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 06:38:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213048#M35243</guid>
      <dc:creator>jkougoulos</dc:creator>
      <dc:date>2024-05-03T06:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213122#M35250</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;thanks for the feedback, indeed sounds complicated… I will take it as a non supported feature &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Since this is a gateway feature, meaning that the connection initiates from the gw, I don’t think that the validation on another non-vsx gateway provides any value in relation to the reachability of the feed.&lt;/P&gt;&lt;P&gt;perhaps the validation is more for the content, which in any case as we talk about a dynamic list is not guaranteed to be always successful even it is validated ok for the first time. So I mean validation for the content should be there always, the initial test on a non-vsx gw does not provide any guarantee.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;errors seem to appear in vsx mode correctly in the log files, so I cannot really understand the issue technically, perhaps with the exception that someone needs to dig the log files in the gw to see the error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously I just see the surface, perhaps there are other complexities under the hood but it is a pity we cannot use this feature.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 14:50:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213122#M35250</guid>
      <dc:creator>jkougoulos</dc:creator>
      <dc:date>2024-05-03T14:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213133#M35252</link>
      <description>&lt;P&gt;Reachability of the feed is a really simple problem to solve. You have all the firewall logs and so on to tell you about problems, after all. Testing the feed is entirely about confirming the firewall application software can parse the contents.&lt;/P&gt;
&lt;P&gt;One of my managements has only VSX firewalls. We were going to use network feeds, but we also don't want to maintain two different feed fetch systems on an ongoing basis, so we ended up using some command line tool which relies on 'fw samp'. I'm not thrilled with this, but at least when troubleshooting we don't have to think about which feed method this particular firewall uses.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 15:28:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213133#M35252</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-05-03T15:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213134#M35253</link>
      <description>&lt;P&gt;Back when I brought this issue up with R&amp;amp;D a few months ago, I thought we had agreed that it would be fine to run Network Feeds on VSX subject to the limitations I previously discussed and possibly others.&lt;BR /&gt;The documentation never got updated to this fact.&lt;BR /&gt;Let me double check this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 15:29:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213134#M35253</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-03T15:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213187#M35257</link>
      <description>&lt;P&gt;It only provides value insofar as the underlying functionality used to test the feed is not available in VSX for whatever reason.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 23:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213187#M35257</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-03T23:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213188#M35258</link>
      <description>&lt;P&gt;My educated guess is that TAC might not help you if things break, as sk states external network feeds are not supported. Possibly best effort support, but you should confirm.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 23:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213188#M35258</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-03T23:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213560#M35322</link>
      <description>&lt;P&gt;Just to follow up on this after consulting with R&amp;amp;D:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;R82 will add support for the "Test Feed" option in Network Feeds for a VS.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A future R81.20 JHF will include support for the "Test Feed" option from a VS (&lt;SPAN&gt;PRJ-53794); ETA unknown at this time.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Which means, at the very least, this will be officially supported in the future.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 01:45:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213560#M35322</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-08T01:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213589#M35339</link>
      <description>&lt;P&gt;Thank you very much for the follow up!&lt;/P&gt;&lt;P&gt;So, I guess the workaround for now for us with VSX only,&amp;nbsp; is something like install a non-VSX gateway eg&amp;nbsp; lab/trial edition to test the feed and then push to VSX, until the test feed feature arrives on VS.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 07:46:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213589#M35339</guid>
      <dc:creator>jkougoulos</dc:creator>
      <dc:date>2024-05-08T07:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213696#M35360</link>
      <description>&lt;P&gt;Correct, you need a non-VSX gateway to "test" the feed currently.&lt;BR /&gt;Once that's done, it can be deployed to VSX gateways.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 22:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/213696#M35360</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-08T22:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/241130#M40232</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;I would like to ask if by any chance you have updates about PRJ-53794.&lt;/P&gt;&lt;P&gt;Maybe we can go with "limited support" for some time, but then I'm facing another challenge how to trust the server certificate when using TLS which for certain will be audit requirement. Can we somehow import the certificate as trusted in given CMA? Unfortunately, we do not have regular GW in the CMA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other option could be the use of generic data center object, but that requires JSON and we are using flat file format for all other vendors. Also, this option seems to be different as CMA server itself is checking for the updates on the external server and then is updating the GWs/VSs if needed.&lt;/P&gt;&lt;P&gt;Another strange thing I came across when testing both of these features is that they do not affect existing sessions. The session has to be terminated and re-initiated to get blocked. The Connection persistence option has no effect on this. For sure the Rematch is working when tested with regular rule not using network feed OR data center object.&lt;/P&gt;&lt;P&gt;This is crucial as this is intended as SOC automated tool which must block the connection immediately.&lt;/P&gt;&lt;P&gt;Do you think there is any other option to achieve this except the two mentioned?&lt;/P&gt;&lt;P&gt;As always, thank you for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 14:02:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/241130#M40232</guid>
      <dc:creator>ArchVile</dc:creator>
      <dc:date>2025-02-13T14:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/241165#M40243</link>
      <description>&lt;P&gt;For an immediate block, use DoS mitigation rules:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112454" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112454&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC will have to comment on&amp;nbsp;&lt;SPAN&gt;PRJ-53794.&lt;BR /&gt;&lt;/SPAN&gt;As for importing a different CA to trust in this situation, don't know offhand if it's possible (especially if the UI doesn't work).&lt;/P&gt;
&lt;P&gt;And yes, the Generic Data Center object operates the way you describe (CMA checks and updates gateways as needed).&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 00:00:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/241165#M40243</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-14T00:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247399#M41346</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Network Feeds, it is compatible and possible to use it in VSX environments with Gaia R81.20 Take 84?&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 02:46:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247399#M41346</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-04-26T02:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247400#M41347</link>
      <description>&lt;P&gt;Im pretty sure its fine, did not see any limitations about it in below link.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 03:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247400#M41347</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-26T03:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247401#M41348</link>
      <description>&lt;P&gt;Do we know if this is know supported, as of R82?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 08:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247401#M41348</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-04-26T08:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Network Feeds and VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247402#M41349</link>
      <description>&lt;P&gt;Looks like the sk was updated March 17th 2025, but table still says not supported for net feeds for VSX as of R82.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk79700" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk79700&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 10:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/247402#M41349</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-26T10:58:04Z</dc:date>
    </item>
  </channel>
</rss>

